NIST Assessment and Cybersecurity Roadmap for A Large County
- Strategic Alliance Consulting
- Dec 16, 2024
- 4 min read

Situation
A Large County with more than1 million customers and $1 billion in revenue needed to evaluate their state of readiness against cyber attacks, such as ransomware. The organization had never conducted a comprehensive cybersecurity assessment and wanted an expert partner to step in and spearhead the assessment, analysis, and remediation. Based off its experience leading internal and external penetration testing, Strategic Alliance Consulting (SAC) recommended a NIST Cyber-Security Framework (NIST CSF) assessment for identifying the gaps in their governance, risk management, and compliance policies and procedures.
NIST Assessment Solution
SAC utilized its proprietary methodology and quickly deployed an expert team to implement the standardized NIST assessment, which included the following steps:
Interview the stakeholders & identify existing policies and procedures
Study and analyze the data to identify any gaps
Develop Strategic and Tactical Recommendations
Document a 12-month Cybersecurity Roadmap
Review the results and recommendations with the technical and executive team
The NIST Assessment measured compliance across five functions and 23 categories, which included:
NIST Assessment Results
After several weeks of work, SAC concluded that the organization was partially compliant in 19 of the 23 categories, while non-compliant in 4. SAC’s team provided recommendations for:
New programs or overhauls in areas like Incident Response, Risk Management, Vendor Management, Business Continuity / Disaster Recovery, and Security Training
Formal policies / procedures and documentation to promote cybersecurity maturity
Improved communications and oversight across departments
The final component of the project was the 12-month NIST compliance roadmap which included a schedule for planning and remediation of the identified compliance issues, and milestones for benchmarking and continual cybersecurity improvement.
Thanks to the NIST assessment, the organization was now armed with the knowledge and framework to continue to mature its cybersecurity posture across its infrastructure, people, and processes.






Comments